!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

105 Members
Another day, another cert renewal43 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
3 Jun 2024
@arianvp:matrix.orgArian So the rate-limit issue is probably less of a problem; unless you have A lot of domains 10:01:25
@sandro:supersandro.deSandro 🐧As said, I've updated 25 VMs or so with that and the only problem I've ran into was that the one DNS challenge could not create records for all aliases10:01:42
@sandro:supersandro.deSandro 🐧All other http challenges worked like a charm and I probably updated a VM every 5 to 10 minutes10:02:08
@sandro:supersandro.deSandro 🐧
In reply to @arianvp:matrix.org
So the rate-limit issue is probably less of a problem; unless you have A lot of domains
If the domains are similar, I always use the DNS challenge to avoid sich scenarios in case of data loss but probably not everyone is doing that
10:03:00
@arianvp:matrix.orgArianRedacted or Malformed Event10:05:25
@arianvp:matrix.orgArianWe also have https://github.com/NixOS/nixpkgs/pull/244511 which limits concurrent domain creation. I didn't realise that landed10:05:55
@arianvp:matrix.orgArianSo... the rate limit concern is probably not so big. This is just a problem with people with CAA records. I think I'm okay with just double checking this is in the release notes and if not add it10:06:21
@arianvp:matrix.orgArianIf ya'll agree lets go with a prominent entry in the release notes. If someone has energy to do a state convergence PR that's a nice to have but probably not as urgent as I initially thought10:09:21
@sandro:supersandro.deSandro 🐧
In reply to @arianvp:matrix.org
We also have https://github.com/NixOS/nixpkgs/pull/244511 which limits concurrent domain creation. I didn't realise that landed
I think that is mainly there to prevent going immediately into the rate limit of something fails
10:12:21

Show newer messages


Back to Room ListRoom Version: 6